CVE-2020-36139: XSS
Published Jun 4, 2021
·Updated
BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.
Affected Software
1 affected component
bloofox bloofoxCMS=0.5.2.1
Event History
Jun 4, 2021
CVE Published
via MITRE·03:04 PM
Data Sourced
via MITRE·03:04 PM
Description
Frequently Asked Questions
1
What is CVE-2020-36139?
CVE-2020-36139 is a Reflected Cross-Site Scripting (XSS) vulnerability in BloofoxCMS version 0.5.2.1.
2
How does CVE-2020-36139 affect BloofoxCMS?
CVE-2020-36139 allows an attacker to inject a XSS payload through the 'fileurl' parameter in BloofoxCMS 0.5.2.1.
3
What is the severity of CVE-2020-36139?
The severity of CVE-2020-36139 is medium with a CVSS score of 5.4.
4
How can I fix CVE-2020-36139?
To fix CVE-2020-36139, it is recommended to update BloofoxCMS to a version that is not affected by this vulnerability.
5
Where can I find more information about CVE-2020-36139?
You can find more information about CVE-2020-36139 in the following reference: https://muteb.io/2020/12/29/BloofoxCMS-Multiple-Vulnerabilities.html